We host the domain but we don't know who's machines they are.
They are not connected over VPN.
Not sure what they are doing, but we get these events every hour and it does fill the log.
Would be good to stop them somehow.

On your firewall, block those 2 IP addresses or filter those ports out. Right now it appears these two computers are attempting some sort of hack over multiple ports. You should have some sort of filtering for inbound ports that are not required or an "allow" list of the few inbound that are.

Or notify the ISP that these guys are attempting to hack you.

0

Featured Post

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that.
In this Article I'll show how to deploy printers automatically with group policy and then using security fil…

In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…

In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB.
To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…